Back to skill

Security audit

karpathy-llm-wiki

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently manages a local markdown wiki and its persistent file writes are disclosed and aligned with that purpose.

Install only from a trusted ClawHub/npm source, preferably with a pinned or verified installer version. Expect the skill to create and modify files under the configured wiki root and to log wiki queries; avoid placing sensitive sources there unless you want the agent to summarize and cross-link them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:10
Finding

Unpinned Package Execution Through Mutable Latest Release

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 8–11
Vulnerability Type: Unsafe third-party package installation
Risk Level: Medium

Vulnerable Code

markdown
## Install

```bash
npx clawhub@latest install karpathy-llm-wiki
text

### Technical Analysis

The documented installation command invokes `npx` with the mutable `clawhub@latest` package reference. Depending on the local environment and cache state, `npx` can retrieve and execute package code from the configured npm registry.

Because `latest` is a mutable distribution tag rather than a reviewed, immutable version, the code executed by this command can change after the Skill has been audited. The project provides no pinned version, lockfile, package integrity digest, or provenance-verification procedure for this installation path.

This creates a supply-chain trust gap: compromise of the package publisher account, registry release channel, or a future package release could cause users following the documented instructions to execute code that was not present during this audit.

### Attack Path

1. An attacker compromises the `clawhub` publishing account or otherwise gains control over the package version referenced by the `latest` distribution tag.
2. The attacker publishes a malicious release and assigns it to `latest`.
3. A user follows the installation instructions and runs `npx clawhub@latest install karpathy-llm-wiki`.
4. `npx` retrieves the attacker-controlled package through the configured package registry.
5. The package's CLI entry point or applicable lifecycle behavior executes with the privileges of the user running the command.
6. The malicious package can access or modify resources available to that user before or while presenting apparently legitimate installation behavior.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the permissions of the installing user. The access
...[truncated 639 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an explicitly reviewed package version, for example:
    bash
    npx clawhub@<reviewed-version> install karpathy-llm-wiki
    
  2. Document the expected package publisher, registry, version, and release provenance so users can verify that they are installing the intended artifact.
  3. Where supported, verify the package's integrity digest or signed provenance before execution.
  4. Use lockfiles and reproducible installation procedures in automated or development environments.
  5. Review new package versions before updating the pinned version rather than automatically following the latest tag.
  6. Advise users to run installation under a least-privileged account and avoid exposing unnecessary credentials in the installation environment.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx clawhub@latest install karpathy-llm-wiki, which fetches and executes the latest published package version at install time rather than a reviewed, immutable version. This creates a supply-chain risk: if the package or one of its dependencies is compromised later, users following the documentation may execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description is very broad and can be invoked for multiple loosely defined actions such as ingesting sources, querying the wiki, health checks, or initializing a new wiki. Ambiguous trigger boundaries increase the chance the agent activates in the wrong context and performs unintended file reads/writes on a persistent knowledge base, which is more sensitive because this skill modifies local state over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.